How to report security vulnerabilities to Yomly responsibly.
Yomly takes the security of its platform and client data seriously. We welcome reports from security researchers, clients, and the broader community when potential vulnerabilities are identified. This policy sets out how to report vulnerabilities to us, what you can expect from us in return, and the boundaries within which responsible research may be conducted. |
If you discover a security vulnerability in any Yomly system or service and report it to us in good faith, in accordance with this policy, we commit to:
The following Yomly-owned assets are in scope for responsible disclosure:
The following are explicitly out of scope and should not be tested:
To report a vulnerability, email disclosure@yomly[.]com with the subject line: ‘Vulnerability Disclosure’.
Please include in your report:
Yomly will not take legal action against individuals who discover and report vulnerabilities in good faith, provided they:
This safe harbour applies to the individual who originally discovered and reported the vulnerability. It does not extend to third parties or to disclosures made outside the terms of this policy.
When conducting security research on Yomly systems, you must:
Yomly follows a coordinated disclosure model. We request that researchers allow us a reasonable period, typically 90 days, to investigate and remediate a reported vulnerability before any public disclosure. If we are unable to resolve the issue within this period, we will discuss an appropriate timeline with you.
We may credit researchers who report valid vulnerabilities in accordance with this policy, subject to the researcher’s consent. We do not currently operate a paid bug bounty programme.
Where a vulnerability has the potential to affect client data or platform availability, we will notify affected clients in accordance with our incident response process and applicable regulatory notification obligations. The timeline and scope of client notification will be determined on a case-by-case basis based on the nature and severity of the issue.
© 2026 Yomly. All rights reserved.
See how Yomly helps companies with 250+ employees automate payroll, compliance, and HR operations across countries
Trusted By 250+ Enterprises Across The Globe